I read the recent Gartner MQ for SASE Platforms 2026, and it was a thought-provoking analysis about the current SASE market and vendors. I work with SASE solutions in my job, and this report confirms that SASE is still a complex equation for the whole industry. I’ll take a look at what the Gartner report says and put my views on it.
SASE Market
SASE platforms consist of two mandatory parts SD-WAN and SSE. Earlier, there was a best-of-breed division between network and security platforms, especially in bigger enterprises, but now it’s clear that a single-vendor SASE platform is the better way to go in most cases. Vendors are making efforts to collect all functions and features together for a complete platform. Although consolidating to one vendor and platform is a huge win, SD-WAN and SSE are still too often separate parts of service. SD-WAN is now a standard WAN building block for on-prem networking and entry to SASE, but SSE adoption clearly lacks. There are many reasons for that, as you can see further.
What is surprising at first sight is that the number of active customers is so low. There is a lot of talk and hype for SASE, but numbers tell the truth. Gartner estimates a total of 25 000 SASE platform customers globally. Palo Alto is the leader in adoption with 6500 active customers. Versa, Cloudflare, Cato, Fortinet, and Netskope follow with a few thousand customers each.
If you put the numbers in perspective, there are 300 million enterprises in the world and 25000 of them use SASE functionality somehow today. That’s 0,008 percent of all enterprises! If you compare Palo Alto’s SASE and firewall customer numbers, it’s 6500 vs. 80 000. That’s already 8% of FW customers have adopted the full SASE platform. Fortinet has a different ratio 0,3% with 3000 SASE and 900 000 firewall customers. Well, that’s a bit of an irrational comparison but gives some perspective. Comparing EDR/XDR customer base, the number is about the same as SASE for Palo Alto, but Crowdstrike has about 30 000 customers and Sentinel One 13 000, which is four or two times more than Palo Alto in that EDR category.
After crunching numbers, SASE customer numbers start looking more reasonable or even high. You have to remember that SASE target customers are mostly in the mid-size and large enterprises, but still I think this highlights that SASE is a young and still maturing technology. There’s a lot to digest. SASE adoption will need a holistic approach, meaning difficult, phased, and slow deployment progress. Vendor pricing models don’t help either.
Leading vendor Palo Alto takes 26% market share of total SASE customers, and five followers capture about 10-20% shares each too. They are impressive shares, meaning that the market is already consolidated into the top 10 players. Gartner estimates there are 15-20 fully featured SASE platforms in the market, but half of them seem to be in the “niche” category at global enterprise scale. Aryaka, Barracuda, Cradlepoint, Sonicwall, and Huawei have relevant technology but don’t have enough market power to get into Gartner’s analysis. Vendors that don’t provide full platform capabilities fall into Gartner’s niche category, which means partial solutions or geographical coverage.
Gartner also published separate MQ for SSE, which is yet another story. It focuses on cloud and client-based products where Palo Alto, Netskope, and Zscaler dominate, and vendor choices are even more limited.
Financial Profiles
An interesting mention of vendor strength/cautions is the financial profile. Palo Alto, Fortinet, Zscaler, and Checkpoint are listed as strong in financial metrics. Netskope and Cato have weaker positions, and that means they may be subject to acquisition or merger in the future. Looks like traditional incumbent network firewall vendors will take the market. SASE pioneer Zscaler, which started in SSE, pushes itself respectfully to platform play. Versa is another software company that managed to take the networking side seriously to build a credible platform. Versa is a mid-sized American company but small and invisible in major SASE platform comparisons.
SD-WAN And Hardware
Zscaler and Versa take us to SD-WAN and on-prem networking dilemma of SASE technology. You can be a glorious SSE vendor, but SD-WAN is a mandatory part of SASE, and it’s different. Networking on-prem sites needs hardware. Virtual VM-based gateways are nice and easy, but they need a hypervisor and servers to run. Less and less enterprises have on-prem servers left, and deploying new servers is way too hard, expensive, and eventually doomed. Zscaler made a bold move a few years ago to provide physical appliances and overturned its decision to stay away from SD-WAN. Versa relies purely on software in its own OS, but sells x86 whiteboxes where software runs. SASE platform players must provide SD-WAN hardware appliances, and that feels too often like a bolted-on solution, even with networking vendors.
Fortinet is the only vendor that has full-scale SD-WAN appliances which happens to be Fortigate NGFW. The firewall appliance has built-in SD-WAN, not the opposite. This means Fortinet offers all possible networking and security functions in the same box in a cost-effective way, which is a very attractive solution. Other vendors provide lightweight SD-WAN gateways with limited firewalling and networking capabilities, and the intelligent service edge is located in the cloud. If you do e.g. internet breakout and network segmentation on sites, NGFW firewalling and proper networking functions are a must. If it means deploying a separate firewall device along the SD-WAN appliance, it adds complexity and parallel solutions, meaning also more installation and maintenance burden.
Management And Customer Experience
Gartner gives good ratings for Cato and Netskope for management portals and customer experience. I thought that cloud native SSE vendors are better at providing easy, user-friendly management, but Zscaler, Versa, Palo Alto, and Fortinet score badly, although providing a unified portal. So, the customer experience and the management portal are two different things. I would emphasize customer experience because SASE policy management is a strenuous job, and a good portal and AI assistants could make it more pleasant to operate. Vendors are responding by pushing unified networking and security management to provide simplicity.
Features And Development
SD-WAN and SSE, networking and security are converging on platforms. I think all platforms provide standard features to build a working solution, but not all vendors are equal. Customers prefer security features, and SSE is usually the place where advanced security happens. I would remind again that local networking and security features on-site matter too, because you need to be able to do networking and security basics properly. Central unified management and distributed execution would be best in my opinion.
AI assistants and agents are basic functionality on all platforms to help with daily tasks. Palo Alto and Zscaler take NetSecOps automation further to automate workflows. Netskope provides deep security functions from the cloud, but Fortinet and Versa offer broad hybrid security covering the on-prem part also. Palo Alto understands security needs and roadmap well, but it has limitations on ION appliance’s firewall functionality, which forces SD-WAN to operate more in a cloud-centric model compared to Fortinet and Versa. I have long wondered why ION still exists if Palo Alto had excellent PAN-OS FW where SD-WAN could be integrated.
Cato has strong unified security, especially for agentless devices. Unmanaged devices and non-human identities concern customers and are now the new frontier of SASE. A secure enterprise browser is making way to all platforms, which makes sense in a browser-operated and content-risky world. All vendors follow the hype and add GenAI security features on platforms. Vendors also expand to adjacent security solutions like EDR, DLP, DSPM, SSPM, NDR, and even basic SD-Branch LAN networking. Gartner warns vendors for overplatforming, which may lead to quality problems and eventually affect customer satisfaction and loyalty.
Market Understanding
In terms of understanding market needs, Palo Alto seems to be the visionary leader who fills the unmet gaps. Cato has been an early adopter of new solutions responding to market needs, and it continues to innovate around AI security. Netskope innovates maybe too much around AI and is at risk of forgetting fundamental SASE functions, which then may lead to positioning problems. Zscaler is balancing between security and networking, weighing more to the security side, which then weakens its position in SD-WAN use cases.
POPs And Infrastructure
Global SASE infrastructure, which is dense enough to cover necessary countries and geographies, is mandatory but costly. I think this is the main reason for high SASE pricing. Most providers have now own POP infrastructure, and they are less dependent on costly public cloud. Gartner notes that some vendors are expected to exit the market due to the high cost of maintaining the platform and technology. I doubt too that dedicated massive global infrastructure for every vendor is too much in the long run. Mergers and consolidation must happen. Look what happened to the CDN industry and how mobile operators share infrastructure more and more.
Cloudflare is the clear leader in POP locations due to its general distributed cloud platform. I guess Fortinet and Zscaler have the second-largest POP networks, about half of Cloudflare’s reach. Other vendors have around 100 POPs, which I think is like a “standard” number and enough to cover enterprise needs decently in most cases.
Like in public cloud, sovereign SASE is entering the market, and makes it possible to localize services and data to on-prem. I’m not sure how to think about this. A local instance makes sense to provide better performance in remote markets or performance-critical environments. Sovereign SASE also offers MSPs the flexibility to provide services for local and smaller customers. But there are always limitations and restrictions to consider. Some customers might look for owning the control and data, but most, if not all, SASE platforms already run in EU countries under regulated infrastructure. Gartner reminds that on-prem deployment doesn’t directly mean a sovereign solution. SASE management portal and control plane most probably don’t run in local nodes but somewhere else. Still, some vendors like Versa support fully air-gapped deployment.
Pricing
Customers want simple pricing models, which is obvious. Cloudflare and Versa respond to that and are competitively priced. I think Fortinet is competitive too, and Zscaler sits in the middle tier. Palo Alto, Cato, and Netskope are pricier, and Netskope’s pricing model is the most complex. Probably there is some correlation between price and features, but every customer should evaluate feature valuation against their needs and priorities.
Overall, pricing is usually per user, and a license is purchased in advance for at least a year, usually three to five years. Therefore, scalability and flexibility are rigid, and in my understanding, it’s because vendors must reserve and secure infrastructure costs for customer instances in advance. Some vendors add sites or bandwidth in the pricing mix, which makes the equation more complex right away. Also, SASE on-prem connectors often need separate licenses, which doesn’t make much sense for me. Prices have come down a bit, and vendors and customers are trying to find each other and satisfactory pricing levels.
SASE packs so many features together that a pragmatic way is to bundle or tier them into a few options. As a customer or reseller, I would expect simple and predictable per-user licensing that is easy to estimate and calculate. Bundles are nice if features and price are aligned properly. Also, vendors should move from yearly license commitments towards more scalable SaaS-style monthly based pricing models. I think this will happen eventually when SASE matures further, and adoption grows.